Privacy Policy — UBC HR Assistant
Effective Date: May 2026 Maintained by: Digital Experience Lab (DxL), University of British Columbia Contact: digitalexperience.lab@ubc.ca
1. Purpose
This Privacy Policy outlines how the UBC HR Assistant collects, uses, retains, and protects information. The service provides UBC staff and faculty with AI-assisted answers to HR policy questions, drawing only from official UBC HR knowledge sources.
2. Information Collected
The UBC HR Assistant may collect:
- Chat messages you type into the interface (questions only — do not include personal details).
- Session metadata: login timestamps and conversation identifiers.
- System logs: interaction records retained per UBC ISS M8 requirements.
The chatbot does not collect, store, or process your personal HR records, employee ID, salary, medical information, or any account details. It cannot access Workday, PeopleSoft, or any HR system of record.
3. What Not to Include
Do not include the following in your chat messages:
- Your name, employee ID, SIN, date of birth, or address.
- Medical diagnoses, doctor notes, or personal health information.
- Manager names or individual case details.
- Account credentials or passwords.
If you accidentally include personal information, we will not use it. Please rephrase your question in generic terms.
4. Knowledge Sources
The chatbot answers are grounded in approved UBC HR sources only:
- UBC HR Vancouver (hr.ubc.ca)
- UBC HR Okanagan (hr.ok.ubc.ca)
- UBC Staff Pension Plan (staff.pensions.ubc.ca)
- UBC Faculty Pension Plan (faculty.pensions.ubc.ca)
- UBC ServiceNow Knowledge Base (ubc.service-now.com)
The chatbot will say when it cannot find an answer in these sources rather than guessing.
5. Retention and Purging
- Chat history: Automatically purged after 90 days via DynamoDB TTL.
- System logs: Retained per UBC ISS M8 policy.
- Deleting a chat via the interface removes it immediately from the database.
6. Data Residency
All data is stored within UBC's AWS environment in the Canada (Central) region (ca-central-1). No data is sent outside Canada.
7. AI Model Usage
Chat messages are processed by Amazon Bedrock (Claude) via a UBC-managed Bedrock Agent. Input and output data are not used to train AI models by UBC, AWS, or Anthropic.
8. Access and Contact
To request access to or deletion of information associated with your account, contact digitalexperience.lab@ubc.ca.
This policy is subject to change. Contact us if you have questions about the collection, use, or disclosure of your information.